And there is "the law" and "the other law", often times the two being incompatible, so you're kinda left in the middle trying to kinda please both sides.
Like when governments agencies ask to both "disable all tracking of what their employees do on the platform", to ensure private data and GDPR like stuff are ok. They also ask to specifically "enable full logging of all access to their data" for security reasons.
So: "sed -i 's/tracker/logger/g' codebase" and everyone is perfectly happy.